Dynamic scanning (DAST)

AppScan 360° can perform dynamic analysis of an application that runs in a browser or a web API. Use the configuration options available in AppScan 360°, or upload an AppScan Standard configuration (template file) or a full scan file.

The DAST scan wizard offers three paths:
Option Description
Create a new scan Configure and run your scan in using the AppScan 360° wizard options.
  • Upload a recording of the login procedure, if needed.
  • Upload a traffic file (DAST.CONFIG) to ensure that specific parts of the application are covered.

Create a new scan (full configuration)

Upload template file If you have an AppScan Standard template (SCANT) file, you can use it as the configuration for your AppScan 360° scan. This lets you benefit from all the configuration options available in AppScan Standard. An AppScan Standard template also includes the login recording and multistep configuration.

The template does not include a Manual Explore, but you can upload a traffic recording (DAST.CONFIG file) to ensure that specific parts of the application are covered.

Create a new scan from a template file

Upload scan file If you have an AppScan Standard scan (SCAN) file, you can use it as the configuration for your AppScan 360° scan.

Manual Explore, Multistep operations, and Web API files such as a Postman Collection saved in the SCAN file are included in the scan.

You can run a full scan or use the existing Explore date from the file and run only the Test stage of the scan.

Create a new scan from a scan file

Scanning web APIs

When scanning a web API, be aware of the following:

Related topics

For a list of Threat Classes tested for in dynamic analysis, and their related CWEs, see Dynamic analysis.